Re: nmap reveals trinoo_master on router

Robin Sheat <[email protected]> Thu, 19 Oct 2006 10:31:13 +1300
Newsgroups gmane.comp.security.incidents
Message-ID <[email protected]>
--nextPart11170709.r8Eb5TiGEl
Content-Type: text/plain;
  charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

On Thursday 19 October 2006 00:35, [email protected] wrote:
> I am worried about the last two entries. The last nmap was done in Feb th=
is
> year and I have confirmed that the two port entries (tcp 1524/27665) did
> not exist then.
IIRC, 'filtered' from nmap means that there was no response to that probe.=
=20
Normally a test will say 'connection refused' if you try to conenct to a=20
non-existant port. In this case, there was no response at all. In my (fairl=
y=20
limited) experience with that kind of thing, it usually means that the ISP =
or=20
another firewall somewhere are simply dropping the packets. It could well=20
even be an outgoing firewall on the part of the ISP that you're running the=
=20
scan from.

Oh, the relevant section from the nmap man page:

       [...] The state is either open,
       filtered, closed, or unfiltered. Open means that an application on t=
he
       target machine is listening for connections/packets on that port.
       Filtered means that a firewall, filter, or other network obstacle is
       blocking the port so that Nmap cannot tell whether it is open or
       closed.  Closed ports have no application listening on them, though
       they could open up at any time. Ports are classified as unfiltered w=
hen
       they are responsive to Nmap=E2=80=99s probes, but Nmap cannot determ=
ine whether
       they are open or closed. Nmap reports the state combinations
       open|filtered and closed|filtered when it cannot determine which of =
the
       two states describe a port.

=2D-=20
Robin <[email protected]> JabberID: <[email protected]>

Hostes alienigeni me abduxerunt. Qui annus est?

PGP Key 0xA99CEB6D =3D 5957 6D23 8B16 EFAB FEF8  7175 14D3 6485 A99C EB6D

--nextPart11170709.r8Eb5TiGEl
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFFNp0kFNNkhamc620RAu/6AKCRGDR7RAugL+YAN0OVAYqnXc2HyQCeOVd4
beKQD0Mx0GzKdq7cnwkehYY=
=JwkF
-----END PGP SIGNATURE-----

--nextPart11170709.r8Eb5TiGEl--